<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Open source tool for firewall policy and Change management in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110869#M20932</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply, could you please share me the forum link. also is this possible for us to track change management of rule bases using ansible and to check disable rules and expired rules and going to expire rules. im looking for a replacement for "Tufin"&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 07:49:32 GMT</pubDate>
    <dc:creator>Ram1</dc:creator>
    <dc:date>2021-02-16T07:49:32Z</dc:date>
    <item>
      <title>Open source tool for firewall policy and Change management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110828#M20928</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any open source tool which is very good on policy and change management for checkpoint Firewall. To replace tufin, is there any open aousou tool like tufin. If yes please let me know...also can we automate firewall policy and change management using ansible...any other options would be very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 16:57:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110828#M20928</guid>
      <dc:creator>Ram1</dc:creator>
      <dc:date>2021-02-15T16:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Open source tool for firewall policy and Change management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110836#M20929</link>
      <description>&lt;P&gt;We have an Ansible module to manage policy and objects, yes.&lt;BR /&gt;In fact, we have a specific forum on CheckMates for Ansible-related queries.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 18:16:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110836#M20929</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-15T18:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Open source tool for firewall policy and Change management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110869#M20932</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply, could you please share me the forum link. also is this possible for us to track change management of rule bases using ansible and to check disable rules and expired rules and going to expire rules. im looking for a replacement for "Tufin"&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 07:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110869#M20932</guid>
      <dc:creator>Ram1</dc:creator>
      <dc:date>2021-02-16T07:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Open source tool for firewall policy and Change management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110948#M20937</link>
      <description>&lt;P&gt;It's under Products &amp;gt; Developers:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Ansible/bd-p/ansible" target="_blank"&gt;https://community.checkpoint.com/t5/Ansible/bd-p/ansible&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Ansible itself does not provide this functionality, but if all rulebases/objects are built using Ansible and you use something like Git to track changes to the playbooks, you, by default have a way to track this stuff.&lt;BR /&gt;This will only help you with new rulebases/objects created with Ansible, not existing rulebases/objects.&lt;/P&gt;
&lt;P&gt;There is no specific APIs for tracking disabled or expired rules.&lt;BR /&gt;You can query the rules and find them, but that has to be done outside of Ansible using the API.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bottom line: Ansible itself will NOT replace Tufin.&lt;BR /&gt;You can use it to potentially build your own replacement, but a lot of assembly will be required.&lt;BR /&gt;If you're just looking to track configuration changes, there are SmartConsole Extensions that assist with this (requires R80.30 and above):&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/SmartConsole-Extensions/Change-Report/m-p/87322" target="_blank"&gt;https://community.checkpoint.com/t5/SmartConsole-Extensions/Change-Report/m-p/87322&lt;/A&gt;&lt;BR /&gt;It won't be as full-featured as Tufin, of course, which has a lot of additional functionality.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 18:31:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Open-source-tool-for-firewall-policy-and-Change-management/m-p/110948#M20937</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-16T18:31:41Z</dc:date>
    </item>
  </channel>
</rss>

